Since early 2025, the Russian influence network CopyCop (Storm-1516) has launched over 300 fake news and impersonation websites targeting the US, France, Canada, Germany, Armenia, and Moldova. These sites, operated by John Mark Dougan with support from the GRU and CGE, use self-hosted, uncensored LLMs based on Meta’s Llama 3 to generate pro-Russian, anti-Ukraine, and anti-Western content. The network’s expansion includes new languages and regions, with tactics such as deepfakes, fake interviews, and impersonation of media and political entities.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Google Threat Intelligence reported that Russian influence operations have broadened beyond Ukraine to target the United States, the European Union, and NATO countries in campaigns aimed at undermining political stability and transatlantic unity. The report said the operations use fake news sites, direct messaging, and are often coordinated with destructive cyber activity, while Russian cyber groups also use AI tools such as ChatGPT and Gemini to aid malware development, infrastructure setup, and lure creation.
Initial story creation
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcerecordedfuture.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.